hardware-health-check

Pass

Audited by Gen Agent Trust Hub on Aug 6, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill utilizes environment variables (REDFISH_USERNAME, REDFISH_PASSWORD) for authentication, which is a standard and secure practice for managing sensitive credentials in AI agent environments.
  • [SAFE]: The skill implements a strictly read-only diagnostic workflow. It explicitly excludes power control capabilities (such as reset or power cycling) and advises that such actions should be performed via official BMC interfaces under change control, adhering to the principle of least privilege.
  • [SAFE]: The instructions include robust security guidance, warning the agent that BMC credentials are root-equivalent and instructing it never to echo these secrets into logs or reports. It also transparently notes that TLS verification is disabled by default due to the prevalence of self-signed certificates on hardware controllers.
  • [SAFE]: No obfuscation, prompt injection, or suspicious persistence mechanisms were found. The workflows are logically consistent with the stated purpose of hardware health triage.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 6, 2026, 09:47 AM
Security Audit — agent-trust-hub — hardware-health-check